EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified across the CMS and its associated plugins that could allow unauthorized information disclosure, access-control bypass, SQL injection, denial-of-service conditions, credential exposure, account takeover, unintended payment operations, and remote code execution. The issues affect core functionality as well as the MCP, Stripe, Ecommerce, and Import Export plugins. Exploitation generally depends on specific configuration or access conditions, such as exposed query functionality, authentication collections, API-key usage, or enabled plugins.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified across the CMS and its associated plugins that could allow unauthorized information disclosure, access-control bypass, SQL injection, denial-of-service conditions, credential exposure, account takeover, unintended payment operations, and remote code execution. The issues affect core functionality as well as the MCP, Stripe, Ecommerce, and Import Export plugins. Exploitation generally depends on specific configuration or access conditions, such as exposed query functionality, authentication collections, API-key usage, or enabled plugins.[emaillocker id="1283"]
CVE-2026-105805 (CVSS 6.9 — Medium): Sorting readable records could expose limited information about fields the requester was not permitted to read.
CVE-2026-105804 (CVSS 5.7 — Medium): Password hashes use insufficient PBKDF2 iterations.
CVE-2026-105847 (CVSS 7.1 — High): Polymorphic join queries could disclose hidden fields including password-reset tokens.
CVE-2026-105846 (CVSS 6.1 — Medium): It is a vulnerability in Payload that allows attackers to craft redirect links that send guest users to untrusted destinations after authentication.
CVE-2026-105845 (CVSS 9.8 — Critical): It is a SQL injection vulnerability in Payload that allows untrusted users to execute malicious SQL queries through dynamic filters or joins when querying readable collections.
CVE-2026-105851 (CVSS 9.3 — Critical): It is a vulnerability in Payload that allows users to duplicate documents and copy hidden or access-restricted field values that should not be exposed to them.
CVE-2026-105853 (CVSS 7.1 — High): It is a vulnerability in Payload that allows token refresh and password reset responses to expose fields that the requesting user is not authorized to access.
CVE-2026-105852 (CVSS 6.9 — Medium): It is a vulnerability in Payload that allows readable collections to expose information about protected documents in related collections despite access.read constraints.
CVE-2026-105849 (CVSS 7.7 — High): It is a vulnerability in Payload that allows users with read access to other user documents to access active API keys and use them with the target account's permissions.
CVE-2026-105854 (CVSS 8.7 — High): It is a vulnerability in Payload that allows malformed multipart requests to take an extremely long time to process, potentially causing resource exhaustion.
CVE-2026-105855 (CVSS 7.6 — High): It is a vulnerability in Payload that allows users to bypass field-level access.update restrictions on password fields in authentication collections.
CVE-2026-105806 (CVSS 8.6 — High): It is a vulnerability in Payload that allows authenticated users to manage MCP API keys belonging to other accounts, potentially enabling privilege escalation and account takeover.
CVE-2026-105848 (CVSS 6.4 — Medium): It is a vulnerability in Payload that allows authenticated users to perform unintended Stripe operations through the optional Stripe REST proxy.
CVE-2026-105850 (CVSS 8.8 — High): It is a vulnerability in Payload that allows an order confirmation to be processed more than once when using the Stripe payment adapter.
CVE-2026-105844 (CVSS 9.3 — Critical): It is a vulnerability in Payload that allows unauthenticated users to submit and execute remote code when the Import Export plugin is enabled.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-9g87-32v6-3c2r
https://github.com/advisories/GHSA-q6mq-ch85-c8mm
https://github.com/advisories/GHSA-fpww-c55p-cjv6
https://github.com/advisories/GHSA-w84c-53h3-mc2g
https://github.com/advisories/GHSA-v49j-62m6-pgrr
https://github.com/advisories/GHSA-vc4h-q48j-5hcx
https://github.com/advisories/GHSA-xgv3-crq2-6f69
https://github.com/advisories/GHSA-7c34-32v3-j575
https://github.com/advisories/GHSA-238x-w2j9-gwwr
https://github.com/advisories/GHSA-2g7p-5934-q4w7
https://github.com/advisories/GHSA-fx49-4h83-wjv9
https://github.com/advisories/GHSA-2q76-m6w6-qgc6
https://github.com/advisories/GHSA-r9v2-gg2j-22q5
https://github.com/advisories/GHSA-8r29-2mp2-pmrw
https://github.com/advisories/GHSA-qf28-8hc6-vwrp